Jump to content

ibpalle

Smoothwall Staff
  • Posts

    1,661
  • Joined

Everything posted by ibpalle

  1. Just install over the old one. No reboot needed. Main fixes were issues with delivering data to the on-prem smoothwall and additional fixes for the cloud client integration.
  2. The new iDex agent has just gone live on https://software.smoothwall.com for all to download and install. We are communicating this to customers as well.
  3. The purging of iDex is not a solution as such, not for iDex info not being processed or seen. A restart of the iDex agent service can sometimes address this - setup a task on the DCs to restart the iDex service at 1am. We have a new iDex agent coming out soon.
  4. This doesn't sound right - are users logged in but their group mappings are no longer showing? Do you know if the Smoothwall is set to purge iDex info overnight? Go to the https://smoothwall.ip.address:441/admin/hbd and in the bottom of that page, check if purging has been set.
  5. The browser is based on Firefox so should be reasonably compliant - it's certainly not something we have gotten reports of sites not working on. If we could install extensions in Safari that would be better but not an option. I did try to get iDex agent logins working for one customer who explained they had a setup where users logged into their iPads using AD credentials. We tried but all the logins came from the same IP as the iPads were sending the credentials to an on-site device, which then authenticated the user on AD which meant that all iPad logins showed up as coming from the IP of that device - bummer. One-to-one iPads are a bit easier to find a solution for - but shared is a problem, as you all are aware of.
  6. Allowing teachers to do it themselves is possible too - will require some training though Access to editing categories can be given in the user portal.
  7. A great resource for PAC file creation is this: https://findproxyforurl.com/
  8. That is obviously far too high. If the console can be accessed, and I'm sure support would have tried, the top command will give a good idea on what's causing the load. If I had to guess, excessive logging and/or block page generation. Network - settings - advanced. Any auditing policies enabled? Networking - firewall - firewall policies. Any logging enabled in policies? Reports » Settings » Datastore settings. What are the sizes of the logs shown as?
  9. We have a KB with some useful DNS advice and explanation here: https://kb.smoothwall.com/hc/en-us/articles/360003640159
  10. Thank you - do you know what DNS servers your AD DNS are using as forwarders? Also, what DNS does your DHCP set for domain/BYOD users?
  11. The subnets I need are the subnets of the IP addresses configured on the Smoothwall interfaces. What are you using for DNS on the Smoothwall? You can find DNS settings in networking - configuration - DNS.
  12. What are the subnet ranges of the networks the Smoothwall is directly connected to? What is the value of the ARP table size in Network - settings - advanced? What is the value of the SYN backlog queue size in Network - settings - advanced?
  13. The ARP filter setting should only really be enabled in case you have multiple interfaces configured with IPs on the same subnet (Not multiple IPs on the same interface)
  14. Any reason the ARP filter setting is enabled?
  15. Or just use no proxy settings. The source exception in the Guardian section is for the transparent proxy so once the IP has been added, the upstream won't be intercepting it. You can also create a new auth policy for the proxy the system is set to use and use a location object with the server IP and set that to use no authentication.
  16. Yeah - should be enabled by default.
  17. The blockpage itself can be configured to show the username as well. Go to Guardian - block page - Block pages and edit the blockpage advanced setting s to enable showing the username.
  18. For the user identification on the Smoothwall iOS browser, take a look at this KB - the user ID section. https://kb.smoothwall.com/hc/en-us/articles/4404006049810-Installing-Cloud-Filter-for-iOS
  19. Correct - iDex agent and iDex client are 2 separate solutions. The iDex client has been mostly supplanted by the cloud filter extension these days so is rarely used.
  20. Log messages from reports - logs - system after selecting the web proxy from the section drop down may give a clue but definitely give support a call.
  21. Happens for everyone at once or on a case by case basis? When it happens, can clients ping IPs or resolve hostnames? Wifi or cabled?
  22. Perfectly possible to do. The RADIUS info is flowing between Wifi controller/APs and the Smoothwall so clients can still be isolated.
  23. No new developments on the RADIUS side from us so far. Best option is still to send Smoothwall RADIUS accounting while using another solution, like MS NPS to provide RADIUS with a valid certificate setup.
  24. It's not something we get reports of generally. The connection check on the Smoothwall is a DNS lookup using Google DNS. If that fails, Smoothwall may think the connection is down but if it is the only external connection you have, the check failing should not have an effect. You can try disabling the connectivity check on Smoothwall in the external connection to see if that makes a difference. Are your internal DNS servers and/or BYOD/Wifi clients set to use Google for DNS? Also, if you run a ping to another external IP than Google DNS servers, during that time period, does that show connectivity issues? Finally, bandwidth. Check the realtime traffic graphs during the time to see if there's a bunch of downloading going on.
  25. Re DNS - the setup is normally that ISP and other external DNS are used as forwarders and your local AD DNS are used as conditional forwarders for your domain. However, as long as your internal DNS servers are capable of external lookups, your setup will work fine as well. My preferred setup for DNS when using Smoothwall as firewall is to user external DNS as forwarders, internal AD DNS as conditional forwarders for the AD domain and then on the AD servers, use Smoothwall as their forwarder. This makes Smoothwall the common DNS cache for the network and optimises external lookups.
×
×
  • Create New...